In this episode of the Pipeliners Podcast, we revisit our conversation with Clint Bodungen of ThreatGEN. The discussion focuses on the application of gamification and generative AI in professional training, specifically for enhancing cybersecurity and incident response exercises. The episode also explores a PHMSA-sponsored R&D project that is adapting these advanced technologies for the unique operational needs of the pipeline industry, highlighting the development of AI-driven, multiplayer training environments.
Gamification and Generative AI to Improve Training Show Notes, Links, and Insider Terms
- Learn more about the PHMSA R&D Project
- TAKE THE SURVEYS
- Scenario 1: Emergency and Hazardous Condition Response
- Scenario 2: Team Training for Hazardous Condition Response
- Scenario 3: Emergency Response Exercises
- Clint Bodungen is a globally recognized ICS cybersecurity professional and thought leader with 30 years of experience (focusing primarily on industrial cybersecurity, red teaming, and risk assessment). He is the author of two best-selling books, “Hacking Exposed: Industrial Control Systems” and “ChatGPT for Cybersecurity Cookbook.” He is a United States Air Force veteran and has worked for notable cybersecurity firms like Symantec, Booz Allen Hamilton, and Kaspersky Lab, and is currently the Founder/Head of Product Innovation at ThreatGEN as well as the Director of Cyber Innovation at MorganFranklin Cyber. Renowned for his creative approach to cybersecurity education and training, Clint has been at the forefront of integrating gamification and AI applications into cybersecurity training. He created “ThreatGEN® Red vs. Blue”, the world’s first online multiplayer computer designed to teach real-world cybersecurity and “AutoTableTop”, which uses the latest generative AI technology to automate, simplify, and enhance IR tabletop exercises. As AI technology continues to evolve, he hopes to help revolutionize the cybersecurity industry using gamification and generative AI. Connect with Clint on LinkedIn
- ThreatGEN® Red vs. Blue is a revolutionary new game-based cybersecurity simulation and IR tabletop exercise platform .
- ChatGPT is an AI chatbot that uses natural language processing to create humanlike conversational dialogue. The language model can respond to questions and compose various written content, including articles, social media posts, essays, code and emails.
- Gamification is a method of using video game environments or gaming principles to simulate real-life events for training or education purposes.
- AI (Artificial Intelligence) is intelligence demonstrated by machines in contrast to the natural intelligence displayed by humans.
- GenerativeAI is a type of artificial intelligence technology that can produce various types of content, including text, imagery, audio and synthetic data.
- GitHub is a code hosting platform for version control and collaboration. It lets you and others work together on projects from anywhere.
- Stack Overflow is a question and answer website for programmers. It is the flagship site of the Stack Exchange Network. Stack Overflow is the largest, most trusted online community for developers to learn, share their programming knowledge, and build their careers.
- Injects: Challenges or curveballs thrown into a tabletop exercise scenario to simulate unexpected events or issues, used to test the response of participants.
- Machine Learning: A type of AI that enables systems to learn from data and improve performance without explicit programming.
- Neural Networks: A type of machine learning inspired by the structure of the human brain, used for tasks like pattern recognition and decision-making.
- GRC: Governance, Risk, and Compliance, a framework for managing corporate governance, risk management, and compliance with laws and regulations.
- IDS: Intrusion Detection Systems, technology used to monitor network traffic for signs of cyber attacks or unauthorized access.
- PHMSA (Pipeline and Hazardous Materials Safety Administration) ensures the safe transportation of energy and hazardous materials.
Gamification and Generative AI to Improve Training Full Episode Transcript
Russel Treat: Welcome to the “Pipeliners Podcast”, episode 404, sponsored by EnerSys Corporation, providers of POEMS, the Pipeline Operations Excellence Management System, operations and compliance software for the pipeline operator to address safety program management, control room management, and field operations. Find out more about POEMS at enersyscorp.com.
[background music]
Announcer: The Pipeliners Podcast. Where professionals, bubba geeks, and industry insiders share their knowledge and experience about technology, projects, and pipeline operations. Now your host, Russell Treat.
This week, we’re going to speak with Clint Bodungen of ThreatGEN about combining gamification and generative AI to improve training. Hey, Clint. Welcome to the Pipeliners Podcast once again.
Clint Bodungen: Hey, Russel. Good to be back again.
Russel: [laughs] I’m excited about this particular conversation. I’ve asked you to come on and talk about a project that we are doing together, which is a PHMSA-sponsored R&D project. Before we dive into those details, remind the listeners who you are and tell us a little bit about your background in ICS cyber.
Clint: Sure. Before I begin, you mentioned that you’re excited about this particular conversation. Does that mean you haven’t been excited by our past conversations?
Russel: [laughs] I’m always excited about our conversations, Clint.
Clint: OK. I’m just making sure.
Russel: Every single time and always.
Clint: Those who don’t know me, I’m Clint Bodungen and I’ve got about 30 years of experience — it’ll be 30 years this year in April, actually — of cyber experience. I started in the United States Air Force and then in about 2003, I…Let me back up a little bit.
Between the Air Force and 2003, I worked with Symantec, really getting into the nitty-gritty, learning how to write code for IDSs and things. Then in 2003, I had a unique opportunity to go and help secure this thing called SCADA, which I’d never heard of at the time. That was my first foray into industrial cyber and I never looked back.
From then up until about 2013, my career had consisted of industrial cyber or industrial cyber risk management and consulting. I’ve done everything from the GRC side of things, which is governance, risk, and compliance, all the way down in the trenches with pen testing, and software engineering and writing code, vulnerability research.
I’ve worked for well-owned companies and done projects for well-owned companies that our listeners may have heard of. In 2013, I got more into cyber product development. Over the course of my entire career, I’ve always been involved in training, teaching people about industrial cyber and everything like that. This has all been underlaid by training.
In 2013, I was working with my current business partner, Aaron Shbeeb. We thought that a good way to get into cyber training, especially for industrial in terms of how do you train people on this stuff and calls incidents without making real things go boom? We decided to get into using gaming engines to provide training environments, because even in 2013 — almost 10 years ago — gaming engines provided very realistic environments.
This all came about because we’re sitting there playing “Grand Theft Auto,” which is a game you guys have heard of that game, and we’re shooting up a power plant and fighting these bad guys shooting up our…Actually, fighting the good guys shooting up our power plant, and I’m like, hey, we can do that.
My buddy is like, what, go shoot up a power plant? I’m like, let’s not say that out loud. The FBI is probably listening. We can develop a game that can simulate the processes. That’s how we got down that road.
Another funny aspect of that is probably about six weeks into this, when we’re learning how to be a game developer to develop training environments, Aaron goes, maybe we should reach out to my brother. He is getting his PhD in game design. I’m like, yeah. Six weeks later, you tell me this? Thanks. Appreciate that.
Russel: [laughs]
Clint: We started developing these industrial simulations and that was all prototype. We started showing that at conferences and then in 2017, we decided to really productize this thing. We never really could get the simulation of the digital twin thing to take off. I would like to think I was just ahead of my time.
Then in 2019 we had an opportunity to create our first product, which is red versus blue. It was Michael Farnham at Houston Security Conference, HOU.SEC.CON. He said, “Hey, I want you to teach a red versus blue class, red team versus blue team class. Sort of like what INL does.” I’m like, “OK, sure.”
He says, “Can you do it in one day?” I’m like, “No, you can’t do that in one day.” I went back and thought about it. Then it turns out that I was like, “Well, maybe there’s an opportunity for some game development here.” We decided to turn it into more of a strategic level thing, like playing risk for cyber.
We did it. We built a prototype in eight weeks and had it ready to go for the conference. It went over so well, fast forward, we’re able to quit our full time jobs. Really, we changed the name of ThreatGen. It was originally called D Rez, if you’re a Tron fan, and changed the name to ThreatGen.
That’s how we created, officially, ThreatGen and created the Red Team vs. Blue Team game, Red vs. Blue. In that stance, or in that instance we also started really dabbling with Artificial intelligence. Now this is gaming AI, right? We did use machine learning and neural networks to train our AI.
Back then they didn’t have ready to go plug in AI for game development. We created our own custom AI so that you could play against the computer. That’s where we started getting into that. We even worked with open AI a little bit back before anybody knew who they were.
They had this cyber gym project, and we worked with a little…There’s a large software operating company that we also worked with where they are developing red team simulations, red team emulator, and they wanted to use red versus blue to train. We worked with them and started learning about pre trained, or a generative pre trained transformers, GPTs.
Russel: Let me…Clint, I’m sorry to interrupt you. I want to kind of elaborate on a couple of things you’re talking about here. One of the things you talked…You use the term IDS. What is that TLA? What is an IDS?
Clint: IDS back when I was instrumenting. Intrusion detection systems. That’s the things that they detect cyber attacks.
Russel: I want to talk a little bit about how you and I know one another and such. I’ll give a little bit of that background. We at EnerSys, EnerSys started off as a control systems integrator, and we were building SCADA systems when cybersecurity started becoming an issue.
I was looking for someone who understood cybersecurity and understood cybersecurity specifically for industrial control systems. For what I would call distributed industrial control, but SCADA, basically where you have a lot of remote telemetry sites.
Trying to understand what are the real risks and what do we need to be doing in our projects. Through that and through a mutual friend, I got introduced to Clint. We started at that time at Gas Certification Institute, we were doing cyber training and SCADA fundamentals training. Clint was one of our key instructors.
That’s kind of how I got to know Clint. When Clint built the red blue thing, here’s what I’ll say about red blue. It’s difficult if you don’t work in cyber to really understand what cyber is. What is actually the game they’re playing? What is the job they’re doing?
It’s easy to get to, “Well, they’re trying to keep adversarial parties from stealing your data or doing nefarious things inside your systems.” That’s easy to understand, but the how they do it and the decision making space around how they do it, I didn’t understand until I got hands on with red, black, and I’m like…
Clint: Red, blue.
Russel: Yeah, red, blue, sorry. Thank you. Yeah. Until I got hands on with red, blue. Then all of a sudden I’m like, “Oh, I get it now.” I didn’t need to be…I learned in less than an hour, what I’ve been attempting to understand for years because of that game. That for me was kind of like an aha moment.
Then I think you’re probably getting the point where you’re talking about how red brew led to the tabletop. Let me kind of give it back to you and you can talk about that story.
Clint: Yeah. I guess that was actually a good segue because that sets into stage the proper timeline of where we met and with red versus blue. I’ll just reiterate real quick on red versus blue. Yeah, it’s real popular with anyone who is not familiar with cyber.
It’s really popular with our industrial operators because it’s not technical, but it has all the detail and it allows anyone of even no skill to play the part of the hacker and play the red team, and really understand what the process of the red team is, what the threat does by actually getting to be the threat. That’s an advantage of red versus blue.
While I had been doing incident response tabletops throughout my career, there was always an underlining problem with red with a tabletop exercises. They take a long time to plan if you want them to be accurate to the customer’s environment, your environment, if you are doing it, and it’s a lot of detail, a lot of planning, and you don’t get everything right.
You can’t plan for everything. You can never plan for when somebody says, “Oh, you know what? That’s not exactly how our systems work.” Then now your entire exercise is derailed because moving forward it’s not accurate. Or when somebody says. “OK, great. You’re showing me the logs, but what about this? What about that? Can you show me more detail here? What about this?”
If they do that kind of thing, it completely derails. You can’t plan for all the detail they want. Or if you try to, it takes a lot of time. We started attempting to use red versus blue to facilitate tabletop exercises, but it just wasn’t able to get the level of fidelity, the level of detail that we wanted and to be a value.
It was valuable, but it was novel and it wasn’t what customers were looking for. As soon as generative AI, what most people think of is ChatGPT, but there’s the underlying technology is what we’re using now. As soon as that became advanced enough to where we could actually get that to do the heavy lifting, that was revolutionary.
It’s a transformative technology that allowed us to create…Then let me talk to you about…This got developed but it was pretty interesting. By the name tabletop, everybody knows IR tabletop since the response tabletop exercises. It’s called a tabletop because it’s very similar. You quite literally sit around a tabletop and plan.
That’s another thing about IR tabletops is that they’re often dry and boring and there’s a lot of PowerPoint slides or paper on a table and Excel spreadsheets and it’s tedious. There’s also another type of tabletop, which I grew up playing, and some of our listeners may have grown up playing, which is games, tabletop games like Dungeons and Dragons, Shadow Run, or Star Wars.
I was using generative AI to — and as I mentioned before, I’m a software developer — so I was using generative AI to build an app for my kids to help run a tabletop game like Dungeons and Dragons, where it knew all the rules. It knew the players and it would actually be the dungeon master and it was working and I was kind of amazed. “Wow, generative AI is pretty powerful.”
Or AI has got pretty powerful with the advent of generative AI or the expansion of generative AI. I said, “You know what, I wonder if we can translate this to tabletop exercises.” I ported it over to do tabletop exercises for cyber security. I took it to a customer and I was going to actually use red versus blue for a tabletop exercise.
We were at lunch or dinner somewhere, we were eating. I was showing this new product that I, “Hey, look at this thing I’m doing.” He goes, “Is that what we’re using tomorrow?” I said, “No, we’re actually going to use red versus blue.” He’s like, “I don’t want to use this. Let’s try this out.” We used it and went over very well.
Then I took it and I demoed it. Didn’t even have the product marketized on the market yet. I was at a conference, the ICS Cybersecurity Conference in Atlanta. I didn’t even have the product at my booth. I taught a class and I demoed the product there as part of the class.
Afterwards, the Mike Lennon, who facilitates the conference, he came up to me and goes, “Can you do this again tomorrow morning, like for a group of people?” I said, “Sure.” We filled up a room of about 200 people where I did this thing for about an hour.
I did a tabletop using this auto, what we now as we call it AutoTableTop. After that thing, I had a line of people, a huge group of people at my booth wanting to know how they can get it, how they can access it. Wasn’t even a product yet. That’s how AutoTableTop was developed.
Then fast forward to today, AutoTableTop is a production product that many companies use in regular cyber, as well as an industrial. What it does how it uses generative AI is just like…
[crosstalk]
Russel: Before we go there, let me jump back in again. Clint and I have known each other now for quite a long time. Clint is one of those guys that when I’m just wanting to noodle on what’s new and cool and what are you up to, he’s a guy who I call. He’ll tell me about what he’s doing, and I’ll tell him about what I’m doing.
He started telling me about AutoTableTop. I already knew about red blue, but I didn’t know about AutoTableTop. Started telling me about it. I’m like, “No, that can’t be right.”
We get into this conversation. The nature of the conversation is basically, “Well, Clint, I understand how you might be able to build something that would work for cybersecurity, but. I think doing something that I have in mind for pipelining is probably…” It’s like a whole different, big, complicated effort.
Clint kind of challenged me. He says, “Well, look, let’s get…” He fired it up and I logged on and we’re on the phone together and I start walking through. I just do a handful of prompts, like less than a half a dozen prompts about I’m a gas pipeline operator.”
I give it just a few criteria about the nature of the exercise I want to run. then I say, “OK, start.” It’ll run a step through the exercise and give me feedback. Then I would give it feedback. “This is what I’m going to do next.” It would give me more feedback.
I was blown away, using an AI with basically zero training, just how accurate it was. It was really compelling, really compelling. That’s a little bit of the background about what we’re going to talk about in terms of this project that we’re now working on together. Go ahead.
Clint: That’s what I was going to actually mention before. I was going to get to that point. Before this, I was going to say, what it does, it uses the generative AI to automatically…You give it a few settings. You tell it a little bit about who you are, what your company is, what your network looks like, or whatever.
It generates the scenario and then walks you through the scenario. As you’re going through the scenario, it throws out injects, what we refer to as injects, which is that, “Hey, here’s a challenge. Here’s a curve ball.” Those kinds of things. You can ask it things like, “Well, Oh, can you show with the logs on that device?” And it will generate the logs. It keeps a coherent and cohesive…
Russel: Running story.
Clint: …it keeps a cohesive storyline and it remembers all the details from the beginning all the way through, and it builds that storyline. You can’t derail it. If you try to go off on a tangent, it’ll go right with you. That’s where we were. That kind of segues us into the current project. Russel?
Russel: Yeah. Great. The idea that I had and was that we would take the gamification platform, so the threat gen tabletop, and we would take the generative AI and we would build something for pipeliners. What I wanted to accomplish, these are kind of the goals of the project, one is it needs to be multiplayer.
The current red, blue, and the current tabletop are single player…
[crosstalk]
Clint: Let’s take red versus blue because red versus blue is multi…It is kind of sweet. This is about AutoTableTop though. Yeah, it’s designed to be a facilitator’s tool. The current iteration is designed to have a facilitator putting this up on a one big display, like a projector, sort of like the way tabletops run now.
Russel: What I wanted is to turn it more into a multiplayer game, because in pipelining, there’s a need for training there’s team training requirements, which are part of the control room management rule that require multiple people that interact with the control room to train together. There’s interest in the effectiveness and efficiency of the communications when you do that.
Then, of course, there’s emergency response training. In that kind of situation, a lot of operators are trying to cast a bigger net and they’re trying to enroll additional stakeholders like first responders, local hospitals, fire departments, police departments, and so forth, and emergency management coordinators into this kind of training.
One of the key ideas was it needs to be multi-player so that multiple people are playing against the AI, if you will.
Clint: Right.
Russel: The other measure or requirement is it needs to create an emotional experience. I’ve talked about this many times in things that I do. There’s a big difference between talking about moving gas through a pipe versus going out and opening a valve on a pipe.
I used to do a lot of SCADA projects. We were doing a lot of gas storage stuff. I had a lot of new engineers out of college and they were doing all the automation, and then we would send them in the field to commission. They used to look at this little graphic on a screen and they’re like, why do I need to wait three minutes for that valve to open?
Then they go into the field and they see a 24-inch, 2,500-psi valve and they’re like, oh. [laughs] It’s a whole new level of reality. One of the other goals is to the extent we can, I want to make this as real-world as possible so that people can actually get some real-world experience.
Clint: Right. What you said about emotion, there’s science that backs all of those in that our emotions, our memories are tied to very specific things. One of the most powerful ways to remember things is, is it functional or useful to you, which is a survival trait.
The more you use something or the more functional and useful it is, then the more you’re likely to remember, which is why hands-on learning works, is building that “muscle memory.” A way to short-circuit that and to shortcut that is to provide emotion.
If you think about it, all of our strongest memories are usually tied to emotion. Of course, there is the aspect of if it’s traumatizing, my brain blacks it out, but in general, emotions is a hard wire to memory.
Russel: Yeah.
Clint: That’s why AI gamification works so well is because it’s adding that emotion. To your point, that is absolutely correct. When you’re doing something like this, when you gamify something or if you make something fun, you’re going through a range of emotions from anger, to guilt, to excitement and all of that.
Russel: If you think about, the military certainly has done some great stuff in this domain and there’s some great things that have been written about this. There is a state you go into when you’re kind of deeply in the doing of the thing that is kind of different and apart.
Some people call that a flow state or other things. The idea is if I can really get people into doing it and trying to do it well, without thinking about the fact they’re being trained, I can really do some very powerful training.
Clint: Right. Yeah, then that’s what things like AutoTableTop is designed to do. It’s make it fun. It’s to provide the emotion of the AI does a really good job of throwing out things that put stress on you and get your blood pumping. It also has you thinking and doing. It’s a combination of a functional reinforcement and emotional reinforcement.
Russel: Again, yeah, well stated. Those are kind of the goals. We’re very fortunate that we submitted this as a proposed project to PHMSA. PHMSA picked it up and is putting up some of the funding, not all of it, but some of the funding. We have a number of major pipeline operators involved.
We also have the Mary Kay O’Connor Process Safety Center from Texas A&M involved. If you’re familiar with A&M and its resources, they have emergency response training for first responders and firefighters. If you ever give an opportunity to go to their facility and get a tour, it’s very impressive. The things that they can do real world simulations of.
Then we also have a gentleman by the name of Jack Willingham, who’s the emergency management coordinator for Yazoo County, Mississippi, and was involved in the Sartatia CO2 incident. He’s also serving on the liquid pipeline advisory council.
We’ve got a very broad base of people who are supporting this project, which I think is awesome. Thanks to PHMSA for making these kinds of funds available to do these kinds of projects, because they’re hard to do for little entrepreneurial companies like us, purely out of pocket, particularly doing them this broadly based.
Clint: Why don’t we first talk a little bit about what this project is and what our goals are, and what we’re trying to achieve before we talk about the different phases.
Russel: All right, go ahead.
Clint: Like Russell stated before, is that auto tabletop is very cyber specific. Or actually maybe I don’t know if you…I know you said this at one conversation. I don’t remember if you said it in this conversation. It’s very cyber specific. One of the items of feedback that Russell had for me was that while it amazed him and it did a good job, it wasn’t perfect.
In addition to making this team base where you can have different people logged in and so you have a facilitator, but then each person has logged in and they can give their own responses, their own actions. We also wanted to have a very specifically trained model.
Instead of using the base model for AutoTableTop, which is fine tuned for cyber, we want to fine tune this specifically for pipeline safety incidents. We want to have a very specific pipeline safety specific aspect of this, but it’s not just AutoTableTop. It’s powered by AutoTableTop, but this is going to be a completely separate and new tool that is specific to pipeline safety training.
Clint: Yeah, I think that, yeah, that’s kind of where I was headed. Because really one of the big things we have to do is we have to gather a whole bunch of information so that we can train a model. A couple of things too, we ought to clarify.
Most people, when you say generative AI, they think ChatGPT. ChatGPT is an Internet facing model. It’s…
[crosstalk]
Clint: It’s just the interface to interact with a model.
Russel: My point is anything that you feed it is available to everybody else. It’s a public model and it gets a lot of its information from the Internet in a general way…
Clint: Let me clarify. AutoTableTop…
Russel: Yeah, please.
Clint: …is also not ChatGPT and the information there is kept private as well. I just want to make sure people make that distinction.
Russel: Yeah, exactly. I mean, that’s where I’m going as a part of this is we want to build a model that is available to be used to support this gaming interface, right? It’s a combination of the two things. It’s the building the model that has all the knowledge it needs to be able to drive the simulations, and then building the gaming interface that allows multiple players to interact with scenarios.
That’s kind of the mechanism and we’re doing that in four major steps. The first step is a research step. We’re going to be gathering data about how are people currently doing emergency response? How are they currently doing team training. We’re going to be looking for operators that are willing to share information.
I should mention that we already have agreements and principles from some operators to share their information. That mechanism is going to be, that information will be shared with the project development team. We will sanitize that information and feed it to the model.
What I mean by sanitize is we’ll strip away any operator identifying information. because we want the model to be trained in a more generic way than that. We want it to be very pipeline specific, but not pipeline or specific, if that makes sense.
There’s a whole kind of data gathering phase. Then there is a deal with that data, constitute it, and feed it to train the model. Then there is a build the multiplayer game phase. Once all that’s done, at the end we’re going to be running exercises and we’re going to be capturing notes.
One of the things we get to do as a PHMSA-sponsored project is we’re going to write a research report at the end of all this effort. Four phases, data gathering, model building, trainer building, and then do the training and capture the information.
We’re going to be looking for as many pipeline operators who would like to participate as possible. We’ll also be looking for first responders and other stakeholders to participate in some of these multiplayer trainings as well. Because I think there’s been opportunities for some really awesome learning. We’ll take a great deal away from the project. Clint, anything you want to add to all of that?
Clint: That one of the really cool outcomes from this will be a pipeline specifically trained large language model. Just real quick for those that may not understand that like I mentioned earlier, ChatGPT is a tool. Just like AutoTableTop is a tool.
Generative AI uses what’s called large language models. That’s what we’re talking about. We’re talking about training a large language model. What that literally is, is a huge model — a database, if you will — of massive corpus of knowledge of a specific subject or multiple subjects.
Then that model is trained using AI neural network to correlate different things in there so that it knows how…If I give it a question or an instruction, it can give me a contextual response that is relative to that prompt that I give it, and it can give me the correct information back from that large model. That’s what we’re talking about. It’s amazingly accurate.
Russel: I think that’s a great way to summarize. Here’s the appeal that I’m making to the industry. We are looking for operators that would like to participate in the project. We’ve already assembled our technical advisory panel, which are those that are kind of going to be deeply leaning into the project.
We’re looking for people that would be willing to be interviewed about their current practices. We’re looking for people who would be willing to data share with appropriate confidentiality and such in place. If you think that your company would have an interest in this, we would very much appreciate it if you would reach out.
Best way to do that, there’s two ways to get in touch with me. One is go to the Pipeliners Podcast network website and just submit a contact us form. Those all come directly to me. Also, you can find me on LinkedIn. Just look for Russell W. Treat on LinkedIn and you’ll find me there. You can just drop me a message on LinkedIn.
If you’re interested or if you just like to talk and learn more, I’d really appreciate you reaching out and asking. I suspect as we go through this process, we’ll have a couple more podcasts and share with the listeners what are we learning along the way? Anything to add to all that Clint?
Clint: No, I think that this is the way of the future in terms of training and doing exercises and things like that. One of the things we didn’t mention, there’s three points I want to mention. Number one if you haven’t gathered anything about what generative AI is, it’s simply this.
It can analyze much larger sets of data than a human can much quicker and much more accurately. It’s literally that’s where it’s different from machine learning. Machine learning is good at categorizing things based a lot of information. Generative AI literally acts like a human in the way that it analyzes things in the way it creates output.
The other thing is, I know there’s probably some listeners out there thinking, “Well, but isn’t…” We kind of touched on this, but I want to explain it a little better, which is, “Is my data safe when I’m putting in this model?” The answer is, this is a private model that nobody else accesses.
When you’re using it, if you have information that you might consider to be private, it’s a private instance, so it doesn’t go out to the cloud, the Internet, the Ethernet of the Internet. It doesn’t go out there and expose your data. Nobody else is accessing it.
Second, like Russell said, we’re not using any of your data for training the model. In fact, the way that AutoTableTop currently works is that none of your exercises, all that data, is saved to the cloud. It’s only saved locally on your computer.
Whenever you send it a prompt, whenever you’re interacting with the model through this tool, it’s sending an encrypted connection from your prompt to the model. It does its thing. It comes up with the answer and sends it back to you.
None of your data is saved in the cloud. It’s not saved in the model. It’s not using the model. It disappears once it gets back to you. Essentially like volatile memory, right? I just want to address those concerns from privacy and a data security perspective.
Russel: That’s really helpful, Clint, for people to understand. The idea is the data collection is about getting as much information as we can to make the model as real-world as possible and to have a lot of information about a lot of things that can happen.
I will say this. It’s fairly simple to get incident data. We can go to places like the NTSB. We can use all the incident reports to train the model. We can go to places like CISA, which has incident information. We can go to news outlets and we can say, here’s some specific things about things that were in the news about incidents, and we can use that to train the model.
There’s a lot of places we can go to gather information about incidents. I think the thing that we’re going to have to rely on the industry for is near misses. Those things that happened where they recorded a near miss and their learnings from that near miss, those are the kinds of things we want to get to be able to train that type of thing into the model as well.
That’s not so much about who was doing it or where it was done, but it was more about what happened. That’ll be the sanitization part because we’ll frame that data or that information in a way that it’s useful to the model.
Clint: I want to clarify too. For the generative AI buffs out there who know what they’re talking about, we’re not actually training a new model from scratch. We’re using a foundation model something like. Llama 3.X, right? We’re taking that base model, the foundation model, and we’re fine tuning it with industry specific data.
What that means is the model already starts with a baseline of information. Like Russell mentioned earlier, when he tried it out, he was surprised. He was blown away with how good it performed, right? What fine tuning does is that number one, it fills in the knowledge gaps. It corrects inaccuracies.
One thing about large language models is that it’s not going to come out and tell you it doesn’t know something. It’s going to give you the next best guess. That’s why sometimes it does what we call hallucinates.
What we do in the fine-tuning process is we take all that information and we run it through tests, and whatever it gives us, we fill with that information and then we interact with it using that information, and then if it comes back with an answer that is wrong, or inaccurate, or could be improved upon, we teach it how to improve that.
Essentially, that’s what fine-tuning is. It’s filling in gaps and correcting inaccuracies from an existing foundation model.
Russel: The other thing I would say about goals of the project — this is probably a good place to wrap up — the other thing I would say about goals of the project is we’re looking to create something that a pipeline operator can use and then add additional training to it that makes it more well-tuned to their particular operation.
A lot of this is we’re early on, there’s a lot of decisions being made and a lot of work to be done, but hopefully, this helps people understand what we’re working on and hopefully, we’ll have some people who hear this that will share it with the appropriate people. We would really look forward to any operator that’d be willing to participate or even ask questions.
Hey, Clint, thanks a bunch. The other thing I’ll say is I’m really looking forward to working with you on this. You and I have been talking a lot together and we’ve done some projects together but we’ve never built anything together. I’m really excited about this. This is going to be fun.
Clint: Yeah, absolutely likewise. We’ve done a lot of projects. We’ve done service projects together. We’ve done training together. This is the first product, so yeah, I’m excited about this.
Russel: Yes, Sir. All right, man. Thanks for being here and we’ll catch you next time.
Clint: Thank you.
Russel: I hope you enjoyed this week’s episode of the Pipeliners Podcast, my conversation with Clint. Just a reminder before you go, you should register to win our customized Pipeliners Podcast YETI tumbler. Just visit pipelinepodcastnetwork.com/win and enter for the drawing.
[background music]
Russel: If you’d like to support the podcast, please leave us a review on Apple Podcasts, Google Play, or Spotify. You can find instructions at pipelinepodcastnetwork.com. If you have ideas, questions, or topics you’d be interested in, please let me know on the contact us page at pipelinepodcastnetwork.com or reach out to me on LinkedIn. Thanks for listening. I’ll talk to you next week.
TAKE THE SURVEYS
- Scenario 1: Emergency and Hazardous Condition Response
- Scenario 2: Team Training for Hazardous Condition Response
- Scenario 3: Emergency Response Exercises



